Cyber Threats Put Water Systems at Risk
As federal attention grows, some states are boosting cybersecurity—but local utilities face continued challenges
America’s water systems are increasingly in hackers’ crosshairs. In recent years, dozens of water utilities experienced cybersecurity attacks that forced them to take systems offline, operate manually, or suspend billing or customer account services. Over just a few days this past July, the FBI received reports of cyber incidents affecting water systems across at least seven states.
Although most incidents have not contaminated water or caused sustained outages, cyber threats are increasing as more utilities adopt internet-connected technologies—often without appropriate safeguards. Preventing, responding to, and recovering from cyberattacks can impose significant costs on utilities, including for cybersecurity training and staff, vulnerability assessments, and software and equipment upgrades.
“Things that even 10 years ago we never thought about are all now adding to the cost of what it takes to run a water supply system,” said Mike Grimm, vice chair of the American Water Works Association’s Water Utility Council, earlier this year.
And these costs come on top of broader fiscal challenges facing water utilities, such as higher construction costs, rising regulatory and environmental demands, and aging infrastructure. In response, the Environmental Protection Agency (EPA) last summer produced a set of recommendations, and some states are beginning to address the issue through administrative rules, legislation, technical assistance, and funding opportunities. But states also are confronting another common challenge—how to help local water systems that already face limited technical and financial capacity and competing infrastructure needs manage growing cyber risks.
Fiscal risks to water systems
Cyberattacks on water systems can include ransomware incidents, breaches of customer data, and intrusions into operational technology that can disrupt service, damage infrastructure, or compromise technologies used to operate and monitor water systems. For example, in July 2026, a series of cyberattacks on water and wastewater utilities in more than 30 communities in Minnesota forced some systems to go offline, disconnect equipment, or rely on manual operations.
And these cyberattacks can have significant fiscal implications, often disrupting billing and revenue collection. For instance, a cyberattack in October 2024 forced American Water, the nation’s largest water utility, to shut down customer systems, including billing, to protect data, which interrupted normal revenue processes. Similarly, a 2019 ransomware attack on Baltimore’s municipal systems prevented the city from issuing water bills for several months and ultimately cost the city an estimated $18 million for IT system repairs and lost or delayed late payment and penalty revenue.
Significant cyber incidents can also affect a utility’s financial position, a risk factor that has garnered the attention of credit rating agencies and investors. “As cyberattacks on operational technology become easier to scale, investors will increasingly need to weigh a borrower’s resilience to absorb an incident’s operational and financial effects, not just the burden of its cyber defenses,” Municipal Market Analytics wrote in August. “Robust cyber hygiene remains necessary, but it is unlikely to be sufficient to eliminate the risk of a successful cyberattack.”
Local governments also must contend with the costs of responding to and recovering from attacks on the water utilities that serve their residents. In Boston, for instance, a 2020 ransomware incident disrupted administrative systems for weeks and forced the city’s water and sewer commission to devote time and resources to restoring normal operations.
How governments are responding
In July 2026, Congress introduced legislation that, if enacted, would support cybersecurity resilience investments for midsize and large drinking water systems. And the EPA, National Security Council, and Cybersecurity and Infrastructure Security Agency have encouraged states to develop action plans and address vulnerabilities. The EPA also has raised concerns that many utilities do not meet existing federal requirements and has endorsed cybersecurity recommendations issued by its Water Sector Cybersecurity Taskforce in 2025 and announced targeted funding to support system resilience.
States are pursuing a range of policy and funding strategies with one common thread—supporting local water and wastewater utilities, which bear a significant share of the costs associated with cybersecurity risks.
For example, last year at the direction of Governor Kathy Hochul (D), New York developed a coordinated multiagency cybersecurity framework for the water sector. The state aligned rulemaking to ensure that regulations from the Department of Health and Department of Environmental Conservation impose similar core requirements for drinking water and wastewater treatment, respectively. These include conducting cybersecurity risk or vulnerability assessments, establishing formal cybersecurity programs, implementing incident response and reporting protocols, and providing operator training. In some cases, larger systems face additional governance requirements.
To support implementation, New York paired these requirements with a $2.5 million grant program, Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements, no-cost technical assistance, and access to free federal cybersecurity assessments to help utilities pay for assessments, planning, and upgrades needed to comply with the new regulations. In August, the governor announced that the program had awarded more than $9 million to support 153 local projects, well beyond the initial appropriation.
Still, the available funding is limited relative to expected costs. State estimates suggest that compliance could require up to $150,000 a year for utilities serving 3,300 to 50,000 people and up to $5 million per year for larger systems.
In Maryland, leaders are combining statutory requirements with planning and implementation support. The Modernize Maryland Act of 2022 requires water and wastewater systems that serve more than 10,000 users and receive state funding to assess their vulnerability to cyberattacks, develop cybersecurity plans where appropriate, and report their findings to the General Assembly. The state built on the law with its 2024 Cybersecurity Action Plan for Water and Wastewater Systems and then expanded the requirements in 2025 to cover systems serving more than 3,300 customers. As of 2024, more than 85% of Maryland residents were served by water systems that had completed cybersecurity assessments.
The Maryland Association of Counties warned that, as introduced, the state’s expanded cybersecurity requirements would “place an untenable fiscal burden on counties already struggling with workforce shortages and hiring freezes, making it extremely difficult to allocate the necessary resources for additional cybersecurity staff and administration.”
To help offset compliance costs, Maryland distributes funding through the federal State and Local Cybersecurity Grant Program, which provides resources for cybersecurity resilience investments. The state has supported participation in this program by using its Local Cybersecurity Support Fund to cover the grant program’s required match. However, the grant program is set to expire in September, and even if federal policymakers renew it, Maryland’s cybersecurity requirements will still impose significant ongoing costs on local entities, including water utilities, which often have strained budgets and revenue bases.
In the face of these challenges, various federal programs can also provide important support to help localities and utilities meet state requirements. The EPA and Cybersecurity and Infrastructure Security Agency’s joint water and wastewater cybersecurity toolkit offers assessments and training, while broader grant programs can help states address systemwide risks. More recently, the federal government launched Project Watershed 250, a pilot initiative in Texas that will provide water utilities with no-cost private sector cybersecurity resources.
Long-standing financing tools, particularly State Revolving Funds—joint federal-state programs that help finance water infrastructure projects—can also support vulnerability assessments, equipment upgrades, and workforce training. However, these resources won’t fully cover costs and are not guaranteed. Federal grant programs are limited in scope and can expire or have their funding cut. As a result, states and utilities will probably need to identify additional funding sources to support long-term cybersecurity investments.
Final thoughts
As cyber risks grow and regulatory requirements increase, local water utilities will face growing pressure to invest in cybersecurity measures despite ongoing funding and capacity constraints. And although states are stepping in with funding, technical assistance, and regulatory frameworks, those resources are limited.
As a result, utilities still must shoulder much of the burden for cybersecurity, which they often then pass on to already stretched ratepayers. Without more consistent or dedicated federal and state funding, the gap between cybersecurity needs and available resources is likely to remain a challenge for the nation’s critical water systems.
Mollie Mills is an officer and Fatima Yousofi is a senior officer with The Pew Charitable Trusts’ state fiscal policy project.